Team Fortress 2

Team Fortress 2

802 ratings
BE WARNED! New phishing bot method!
By ExDe707
Phishing bots have become agressive, and now can destroy your whole precious PC. Be warned about that, and DO NOT TRUST ANYONE GIVING YOU LINKS. Read more in this guide.
   
Award
Favorite
Favorited
Unfavorite
Introduction
Now you might know this:

someone: hey my friend want add u but cant (steam error add him pls [LOLPHISH]
someone2: hey im really interested in ur items but got keys on my main ((: add my [LOLPHISH]

The [LOLPHISH] are links that look like the steam community one but are misspelt. Once you try to log in there, what you entered will be sent to the bot and he will use this information to go into your account and steal your valuable items, if there are any.

BUT, it's not harmless anyone like the above example. The phishing bots have developed another method which is WAY more agressive than the above examples:

agressor: Hi, I want swap this knife, Link to screenshot - [OMGPHISH]

The [OMGPHISH] link looks like a link to a picture sharing website. It is structured like that: picthingy(dot)numbers(dot)domain/img_numbersnumbers.png

HOWEVER: It does NOT lead to a picture or anything. More in the next section.
Where does that link lead?
So we have a new link, and we will examine it.
I will not openly share it to avoid too curious people on clicking on it. I'm dead serious about this.
Is it an image?
Well let's take a look at the image below. I used Web Sniffer for it, It's easy and reveals all details about the site, without visiting it.
Apart from some minor details like the IP of the website, it's host etc. It also reveals if it redirects to any other website. I marked the link with a red outline.
Do you recognize that? It's a direct Google Drive download link. The &confirm=no_antivirus part is where it does NOT give you a warning when you download the file. So it's not an image. But what is the file like?
The script of death
Here I used Virustotal to examine the file. I did this by visiting Virustotal, checking the URL Web Sniffer revealed me and then letting it check the file.
The results are as I expected. 18 smart Antivirus companies have reported the file as a trojan virus.
A trojan virus is like a romanian one. It's sturdy, and once it arrived at it's goal, the computer, it releases it's soldiers, the viruses.
The .scr file extension relates to "Script". It is mainly used for Screensavers, but it's one of the most abused files on any Windows OS, as it easily carries trojans. Once it's done downloading, it will wreak havoc in your PC.
I downloaded it.
Okay you're pretty much screwed right now unless you have a good Antivirus like I do (AVG 2014). If your antivirus does not immedietally recognize the virus, start a full scan of your computer as soon as possible.
My antivirus failed. What happens now?
Now? All your passwords and precious data will be stolen, mainly the steam login informations through brute force. It has the same effect as the old add my friend phish, the bot goes into your account and steals your items.
What can I do against that?
There are many things to do. I'll make a list of what you can do to protect yourself.
  • Do not click on any links. None. Absolutely. If one of your friends asks you to watch a video or something, ask them to give informations about the video so you can search it for yourself on youtube. If you do want to click on links check if they are safe with the methods I used above.
  • As a trader, if you use sites like TF2 Outpost or Bazaar.tf, inform your customers to use trade offers instead of friend adds. If someone adds you, ignore or block them. If a suspicious, dumb looking trade offer appears, report and decline it.
  • If you DO want to accept friend requests, then see if the profile is private, or if it even has the game to trade stuff for. If the profile is private, level 0 or 1, or if it doesn't have said game, ignore it.
  • You might accept a friend request from a safe looking person with a high level. If he sends you the phishing messages, then It's a victim of a phishing bot. Simply unadd him. Don't block him, as he might be a future customer.
  • It is in most cases safe to add people currently playing a game, as bots often do not play games when active. This might change in the future.
  • If you notice that you lost some items, contact Steam Support immedietally.
  • Change your password, your E-Mail, whatever, if you find out you clicked on a phishing link.
  • Always be aware of phishers.
Now they might be obvious and stuff you would do, I advise you to ALWAYS do these.
BONUS: Trolling human phishers.
Thanks for spreading this so far! I didn't really expect this to pop up in the front page of TF2 guides. And recieving an over 50 new comments notification spam.

Thus I'm sharing a well-known method of effectively using the dumbness of human phishers to get items for absolutely free. He has to be human though. It works mostly with the "add my friend" phish.
Here is the link: http://forums.backpack.tf/index.php?/topic/16506-guide-how-to-profit-from-phishers/
And if you don't trust it, check it with the methods above. I take no credit for it.
Conclusion & Feedback
tl;dr Bots use a new method, one click means death.

Feedback about this guide is appreciated. Share this to everyone you know, as it might hit them very hard.

Stay safe!
-Ex
Frequently asked questions (FAQ)
Allright, now I'm getting a handful of friend requests from thankful people. It's nice but y'know, there's a limit in my friends list. So I made this FAQ section to answer the most common questions.

Q: I clicked on a suspicious link but it didn't download anything, am I still safe?
A: I can't really tell, as there's something called browser exploits. Websites can be created in ways to abuse your internet browser features, e.g. Drive-by downloads. Google that if you don't know what that is.
Q: I downloaded something like "steam guard.exe" or "1231sy1sa.scr but deleted it quickly, am I safe?
A: I doubt you really are if you executed the files without your antivirus stopping them. .scr files however execute themselves after they dropped on your PC and do their job instantly. You better run a full computer scan after that, change your password and/ or change your E-Mail. And, most importantly, contact Steam Support within 8 days so they can further secure your account.
Q: OMG ur mah h3ruh pls can w b frwiends 4eva?????
A: You better thank me in the comments section instead of adding me. As I said before my friends list is filling. I appreciate that but don't push it too far.
Q: Can I donate you an item as a thank you?
A: ( ͡o ͜ʖ ͡o)
Q: AVG? Good antivirus? topkek lol no
A: lol yes. Google them rewards.
669 Comments
Go4Pro 15 Mar, 2019 @ 4:50am 
sorry friend but i have to tell you something. i have seen from alot of bots that i purchased items from onbackpack.tf were infact in games. i think those official valve servers where u join and get instantly vote kicked are where these bots hang out. maybe they recognize eachother because theire from the same bot network.
yaha 28 Dec, 2018 @ 3:07pm 
Lol some guy tried to shark me out of an unusual
Adam [CZ] 12 Dec, 2018 @ 7:22pm 
Very aggresive bot!!!
Castle 5 Nov, 2018 @ 2:21pm 
hey so I clicked a link which I think is fucking up my trades now cuz every time I offer a trade to someone it removes the items I want from the person and it makes it a gift from me to the person
weedmancer lol 21 Mar, 2018 @ 5:41pm 
Question, I had a old friend for about 2 months now and he sent me a phishing link (OF COURSE I DIDNT CLICK IT) but before he wasn’t much of a bot (actually played the ga:steamsad:me and had a good inventory) but now he’s a bit, did he get hacked? Pls help
FunnyBunny 21 Dec, 2017 @ 3:28pm 
Rat Crusher 17 Dec, 2017 @ 12:14pm 
Tips; "Dont click links from anyone". Gives a link.

Thus I'm sharing a well-known method of effectively using the dumbness of human phishers to get items for absolutely free. He has to be human though. It works mostly with the "add my friend" phish.
Here is the link: http://forums.backpack.tf/index.php?/topic/16506-guide-how-to-profit-from-phishers/
And if you don't trust it, check it with the methods above. I take no credit for it.
PureGothard 24 Nov, 2016 @ 10:06am 
its says a gzip file is that bad
Mattaladøn 1 Nov, 2016 @ 8:57am 
Is item.exchange safe?
Cöque 28 Aug, 2016 @ 7:34pm 
YEAH BOYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYY